Build a secure generation AI solution using AWS and Zscaler

Machine Learning


Aaron Rohyans, Sr. Major Solutions Architect – Zscaler
by Gina McFarland, Partner Solutions Architect – AWS

This is an image of the Zscaler logo.
zscaler
This is an image that says "Want to work with Zscaler?"

Generated AI is moving rapidly. It shapes how companies build, operate and interact. Organizations use AI workloads across operations, from customer service chatbots and code generation to content creation and automated decision-making systems. According to the Zscaler ThreatLabz 2025 AI Security Report, AI/ML tools use has skyrocketed 36 times compared to the previous year. However, security concerns blocked 60% of this traffic, highlighting the tension between productivity and protection.

This post shows how AWS and Zscaler security controls can help protect your AI workloads while maintaining compliance and data protection.

Zscaler ThreatLabz 2025 AI Security Report

Figure 1 – Zscaler ThreatLabz 2025 AI Security Report

The OWASP Top 10 for LLMS and Generated AI outlines some security considerations for adopting Generated AI. These include managing rapid interactions, implementing model access control, and protecting data during information extraction by implementing retrieved generation (RAG). Gartner's research project emphasizes that by 2028, 25% of corporate violations will go back to AI agents' abuse, highlighting the need for proactive security measures.

AWS and Zscaler provide controls to help ensure the implementation of generated AI, providing visibility, access control, and data protection throughout the development and deployment lifecycle. This approach helps maintain security and compliance while maximizing the benefits of generating AI implementations.

AWS provides enterprise-ready tools for building and deploying generated AI applications. As an AI-driven assistant for business tasks and queries, Amazon Q includes content filtering and access controls that administrators can configure. Amazon Bedrock simplifies generator AI development by accessing key fundamental models from Amazon and other AI companies. Amazon Bedrock Guardrails features automated inference checks to help you validate AI-generated content against domain knowledge with up to 99% accuracy. Amazon Sagemaker, a service for building, training and deploying machine learning models, includes multi-layered security controls throughout the machine learning lifecycle.

Under the shared responsibility model, AWS is responsible for cloud security (the infrastructure that runs AWS services). Customers are responsible for cloud security, including data, applications, access control, and more. Zscaler Zero Trust Exchange helps customers fulfill these responsibilities through globally distributed security solutions. This cloud-native service helps to enhance both security and performance compared to traditional VPNs and firewalls by intermediary connections between users, apps and workloads. By placing applications behind Zero Trust Exchange, businesses can prevent unauthorized users and external networks from accessing them. This architecture helps to separate users and apps from the network, reduce exposure points, and limit the lateral movement of threats while protecting data.

AWS and Zscaler provide end-to-end visibility, zero trust access control, and granular data protection throughout the entire generation AI lifecycle, from infrastructure to input, models and external data.

Better Together: AWS and Zscaler Integrated Security

Zscaler, an AWS advanced technology partner with six AWS competencies, including AI security specialization, complements the secure foundation of AWS across key aspects of the generator AI workflow, including:

  • Input Processing and Prompt Engineering
  • Model Access and Interaction
  • Integration with external data sources including techniques such as RAG

AWS services provide a robust security infrastructure with encryption, fine-grained access control, and compliance standards. Zscaler complements this foundation with zero trust access and inline enforcement through identity-aware access control, data loss prevention (DLP), monitoring and blocking smart input prompts with AI guard, and zero trust egress filtering. Together, AWS and Zscaler solutions protect and maintain compliance with generative AI interactions throughout the AI ​​lifecycle.

1. Quick intake – Ensuring input

All AI interactions begin with prompts indicating inherent security risks. Organizations face the following challenges:

  • Employee carelessly includes sensitive data at the prompt
  • A malicious actor trying to manipulate a model through a created prompt
  • Resource consumption from off topic or poorly developed prompts

AWS and Zscaler provide complementary control to address these risks.

  • Amazon Bedrock Guardrails and Amazon Q Moderation Tools Enforce appropriate model responses and policy compliance.
  • Zscaler's AI Guard Blocks real-time inspection of prompts and responses, jailbreak attempts, offensive content, or inappropriate requests before reaching the model.
  • Zscaler DLP and data protection Enforce policies that help prevent sensitive data leaks throughout the generated AI transactions.
    Zscaler Workflow AutomationFigure 2 – Zscaler Workflow Automation

For example, if someone asks a legal compliance AI assistant about their vacation plans, Amazon Bedrock Guardrails can help maintain answers within defined compliance and regulatory parameters. Zscaler can block requests outside of this topic before reaching the model. This integrated approach optimizes resource usage and focuses on the legal compliance tasks of assistants.

2. Models and Data – Core Security

Generated AI implementations require strong model access control and data governance. Organizations need to consider multiple data security aspects.

  • Model and Data Repository Access Control
  • Data verification for training pipelines
  • Handling of original and regulatory content in model responses

Zscaler offers multiple layers of security to address these challenges. At the infrastructure level, Data Security Attitude Management (DSPM) discovers, classifies and tracks sensitive data across cloud environments to identify false shortages and dangerous access patterns. At the traffic level, inline DLP monitor monitor monitor monitor inputs and outputs help to prevent sensitive data leakage and prevent smart input monitoring screens for unauthorized content.

AWS provides multiple security controls for AI services. AWS Identity and Access Management (IAM) policies and role-based access controls manage who has access to a particular resource. Service-level permissions provide granular control over the functionality of Amazon Bedrock, Amazon Q, and Sagemaker. Additional security features include data encryption, API activity logs over AWS Cloud Trails, and private connections through Amazon Virtual Private Cloud (VPC) endpoints.

For AI training, consider a team that uploads customer data to a shared Amazon S3 bucket. AWS controls provide access restrictions, encryption enforcement, and activity logging. Zscaler's DSPM solution identifies sensitive content and potential misguided appearances. This layered approach helps you protect your data throughout your AI workflow.

3. Searched Generation: Protecting Internet Query Layer

RAG enhances AI applications by incorporating information from internal repository, external sources, or both. This integration requires specific security considerations, particularly with external data on the public Internet.

Zscaler Zero Trust Gateway, a service-based version of Zscaler Cloud Connector Virtual Machine, protects internet-based RAG operations at points of data search by forwarding this traffic over the Zscaler Zero Trust Exchange. Zscaler Secure Web Gateway, a component of Zero Trust Exchange, adds protection by blocking connections to high-risk sites. Filter URLs, capture threats in real time, and enforce Zero Trust Access policies.

AWS supports private, curated data sources through Amazon Bedrock and Amazon Q, allowing organizations to retrieve information from trusted internal knowledge bases and secure endpoints.

Zscaler Rag Protection

If a healthcare chatbot tries to access a fraudulent medical website, Zscaler blocks connections and protects against untrusted sources. Alternatively, you can avoid such queries by preconfiguring Amazon bedrock to fully route the reviewed internal repository.

Governance and regulatory compliance

Companies deploying generated AI must comply with data protection and AI governance regulatory requirements, including personally identifiable information (PII) protection and decision traceability. AWS provides tools such as Amazon Bedrock Guardrails to help you implement the right model behavior, while IAM provides fine-grained access control and permission management.

Zscaler complements these capabilities, providing real-time visibility with detailed audit trajectories of prompt and response traffic, generated AI interactions, and dynamic policy enforcement based on users, content and risk levels. It also provides DLP to meet regulatory requirements and provide detailed logging for security investigations and compliance reports.

Looking ahead: Agent AI

As the generation AI evolves, agent AI represents the next advance in automation. Automatic agents can act independently to complete complex tasks such as IT ticket resolution and data analysis.

Agent AI Security Considerations

Agent AI works with greater autonomy, but ensuring that is built on existing principles.

  • Quick verification Beyond agent-agent interaction
  • Access Governance For models and knowledge bases
  • Data protection Confidential information in agent interactions
  • Secure access control For external sources
  • Maintain operational integrity Between agents through certification and policy enforcement

Organizations using generated AI can extend their existing security controls to address these new requirements, leveraging the proven patterns of this next-generation AI technology.

Take action against AI security

Organizations at every stage of AI adoption need to innovate at scale and at responsible, at a rapid pace, from deploying individual assistants to coordinating autonomous agents.

Let's get started:

.
This is an image that says "Connect to Zscaler"
.


Zscaler – AWS Partner Spotlight

zscalerAWS Advanced Technology Partner has been a leader in Zero Trust for over a decade and has six AWS competency, including AI security specialties. Zscaler Zero Trust Exchange helps protect thousands of customers from cyber threats and data loss by safely connecting users, devices, applications, and workloads. Zero Trust Exchange is distributed globally with over 160 presences, offering cyber threat protection, data protection, risk management, and zero trust access control.

Contact Zscaler | Partner Overview | AWS Marketplace



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *